Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Researchers say credential-stealing campaign used AI to build evasion ‘at every stage’  – CyberScoop
AttackFeed by Joe Wagner | Researchers say credential-stealing campaign used AI to build evasion ‘at every stage’  - CyberScoop

Researchers say credential-stealing campaign used AI to build evasion ‘at every stage’  – CyberScoop

Posted on March 30, 2026 By djohnson
Attack Feeds

A new malware-based credential-stealing campaign, which researchers are calling “DeepLoad,” has been infecting enterprise business IT environments over the past

In a report released Monday, ReliaQuest AI researchers Thassanai McCabe and Andrew Currie say the most relevant feature of this attack is the way it uses artificial intelligence and other engineering “to defeat the controls most organizations rely on, turning one user action into persistent, credential-stealing access.”

DeepLoad is delivered to victims via “QuickFix” social-engineering techniques, such as fake browser prompts or error pages. If the user falls for the scheme, the malware developers — or more likely their AI tools — put a lot of work into building evasion of security technology “at every stage” of the attack chain.

The loader “buries functional code under thousands of meaningless variable assignments,” and the payload runs behind a Windows lock screen process that is “overlooked by security tools” monitoring for threats. ReliaQuest said “the sheer volume” of code padding likely rules out human-only involvement.

“We assess with high confidence that AI was used to build this obfuscation layer,” McCabe and Currie write. “If so, organizations should expect frequent updates to the malware and less time to adapt detection coverage between waves.”

DeepLoad can steal credentials through real-time keylogging, and even if security teams block the initial loader, it was able to persist through backup contingencies.

“In the incidents we investigated, the loader spread to connected USB drives, which means the initial host is unlikely to be the only impacted system,” McCabe and Currie wrote. “Even after cleanup, a hidden persistence mechanism not addressed by standard remediation workflows re-executed the attack three days later.”

ReliaQuest’s research offers more evidence that over the past year, some traditional static cybersecurity practices — such as searching for malware signatures or file-based patterns — may be fast becoming obsolete, as AI models can spin out endless variations of attack tooling with unique signatures.

Other organizations like Google and Anthropic have been sounding the alarm that AI-enhanced cyberattacks are dramatically shrinking the time defenders must respond to a compromise.  

At the RSA Conference in San Francisco this year, experts told CyberScoop that the next two years are set to be a “perfect storm” favoring AI-powered offense, with cybercriminals and nation-states more quickly adapting the technology to add greater speed and scale to their attacks than their defensive counterparts.

McCabe and Currie say the likely continued use of AI to frustrate static analysis monitoring means that defenders will need to shift focus to other indicators of compromise.

“Based on what we’ve observed, organizations must prioritize behavioral, runtime detection—not file-based scanning—to catch this campaign (and similar ones) early,” they wrote. 

The post Researchers say credential-stealing campaign used AI to build evasion ‘at every stage’ appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials  – The Hacker News
Next Post: OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability  – The Hacker News ❯

You may also like

AttackFeed by Joe Wagner | Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1  - The Hacker News
Attack Feeds
Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1  – The Hacker News
March 4, 2026
AttackFeed by Joe Wagner | Hackers Stealing Bank Accounts from iPhone and Android Users Using AI  - Da Vinci Cybersecurity: Leading Cyber Security Services in South Africa.
Attack Feeds
Hackers Stealing Bank Accounts from iPhone and Android Users Using AI  – Da Vinci Cybersecurity: Leading Cyber Security Services in South Africa.
May 21, 2026
AttackFeed by Joe Wagner | CISA chief frets about open-source vulnerabilities, delayed security improvements  - CyberScoop
Attack Feeds
CISA chief frets about open-source vulnerabilities, delayed security improvements  – CyberScoop
May 21, 2026
AttackFeed by Joe Wagner | Researchers say credential-stealing campaign used AI to build evasion ‘at every stage’  - CyberScoop
Attack Feeds
Pentagon cyber official calls advanced AI ‘revolutionary warfare’  – CyberScoop
May 14, 2026
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.